Can IPsec S2S VPN be established from a MAX BR1 Mini when in IP Passthrough mode?

I suspect the answer is No, because that IP address actually belongs to the MAC of the device behind it (Balance One in this case), but the IPsec config option is not blocked out like the Remote Access VPN is in this mode.

What about PepVPN / Speedfusion?

When the BR1 is put in IP Passthrough mode, Remote Access VPN options are greyed out, whereas the IPsec / PepVPN options are not greyed out, thus it would seem that the BR1 can still establish a tunnel when in IP Passthrough mode? How would this be possible when BR1’s WAN IP has been given to the Balance One?